Package        : libzypp
Version        : 14.29.1-2+deb8u1
CVE ID         : CVE-2019-18900

It was discovered that there was an issue where incorrect default
permissions on a HTTP cookie store could have allowed local attackersto read private credentials.

For Debian 8 "Jessie", this issue has been fixed in libzypp version
14.29.1-2+deb8u1.

We recommend that you upgrade your libzypp packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-2132-1: libzypp security update

March 3, 2020
It was discovered that there was an issue where incorrect default permissions on a HTTP cookie store could have allowed local attackers to read private credentials

Summary

We recommend that you upgrade your libzypp packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : libzypp
Version : 14.29.1-2+deb8u1
CVE ID : CVE-2019-18900

Related News